Impact
GitHub Enterprise Server suffered a UI misrepresentation flaw that lets an OAuth application obtain the manage_runners:org permission without it being visibly displayed on the consent screen. An attacker can create such an application and trick a victim into authorizing it, thereby granting the application unintended access to manage the organization’s runners. The flaw, CWE‑451, allows the attacker to add, modify, or delete runners, potentially disrupting CI/CD pipelines. The issue exists in all releases before 3.22 and was addressed in the listed patched versions.
Affected Systems
All GitHub Enterprise Server releases before version 3.22 were affected. The vulnerability was fixed in releases 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20. Administrators should upgrade to one of these patched releases.
Risk and Exploitability
The CVSS score is 4.8, and the EPSS score is below 1%. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a human victim to approve a deceptive OAuth application, typically through social engineering. The likely attack vector is inferred to be a social engineering phishing‑like attack where a user is persuaded to approve a malicious OAuth application. Once authorized, the attacker gains the ability to manage organization runners, which can be used to alter pipeline behavior and potentially disrupt CI/CD operations.
OpenCVE Enrichment